VLDB 2026 Research / reviewers in the wild / expert
Weining Zheng
dblp:254/9916
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0003-3668-3600ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Knowledge-guided large language models are trustworthy API recommenders
Hongwei Wei, Xiaohong Su, Weining Zheng, Wenxing Tao, Yuqian Kuang |
Autom. Softw. Eng. | 3 |
| 2025 | VDExplainer: Sequential decision-making and probability sampling guided statement-level explanation for vulnerability detection
Weining Zheng, Xiaohong Su, Hongwei Wei, Wenxin Tao |
Comput. Secur. | 1 |
| 2024 | SVulDetector: Vulnerability detection based on similarity using tree-based attention and weighted graph embedding mechanisms
Weining Zheng, Xiaohong Su, Hongwei Wei, Wenxin Tao |
Comput. Secur. | 1 |
| 2023 | A Graph Neural Network-Based Smart Contract Vulnerability Detection Method with Artificial Rule
Ziyue Wei, Weining Zheng, Xiaohong Su, Wenxin Tao, Tiantian Wang 0001 |
ICANN (4) | 2 |
| 2023 | Documentation-Guided API Sequence Search without Worrying about the Text-API Semantic GapabstractDevelopers often search for application programming interfaces (APIs) and their usage patterns to speed up the efficiency of software development. This paper focuses on the API sequence search task, which refers to using a function-relevant textual query to search for API sequences mined from open-source software repositories that can implement this function. However, the severe semantic gap between text and API makes it challenging to discover the correspondence between natural language queries and desired API sequences. Therefore, we propose a method called documentation-guided API sequence search (DGAS), through which we do not need to worry about the semantic gap between text and API. Specifically, DGAS consists of documentation-guided cross-modal attention (DGCA) and documentation-guided cross-modal matching (DGCM). DGCA calculates the cross-modal attention map using features extracted from the same modality (i.e., API documentation sequence and textual query) instead of from different modalities (i.e., API sequence and textual query) to bridge the semantic gap during the cross-modal attention phase. Besides, DGCM takes API documentation as supplementary information of API sequence to bridge the semantic gap during the cross-modal matching phase. We use the API documentation to extend the existing dataset for API sequence generation to construct a dataset for API sequence search to evaluate DGAS. Experimental results show that DGAS outperforms the baseline methods. Hongwei Wei, Xiaohong Su, Weining Zheng, Wenxin Tao |
SANER | 3 |
| 2023 | Vulnerability detection through cross-modal feature enhancement and fusion
Wenxin Tao, Xiaohong Su, Jiayuan Wan, Hongwei Wei, Weining Zheng |
Comput. Secur. | 5 |
| 2023 | Multi-bit Data Flow Error Detection Method Based on SDC Vulnerability AnalysisabstractOne of the most difficult data flow errors to detect caused by single-event upsets in space radiation is the Silent Data Corruption (SDC). To solve the problem of multi-bit upsets causing program SDC, an instruction multi-bit SDC vulnerability prediction model based on one-class support vector machine classification is built using SDC vulnerability analysis, which has more accurate vulnerability instruction identification capabilities. By hardening the program with selective instruction redundancy, we propose a multi-bit data flow error detection method for detecting SDC error (SDCVA-OCSVM), aiming to protect the data in the memory or register used by the program. We have also verified the effectiveness of the method through comparative experiments. The method has been verified to have a higher error detection rate and lower code size and time overhead. Zujia Yan, Yi Zhuang 0002, Weining Zheng, Jingjing Gu |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2023 | A Hypothesis Testing-based Framework for Software Cross-modal Retrieval in Heterogeneous Semantic SpacesabstractSoftware cross-modal retrieval is a popular yet challenging direction, such as bug localization and code search. Previous studies generally map natural language texts and codes into a homogeneous semantic space for similarity measurement. However, it is not easy to accurately capture their similar semantics in a homogeneous semantic space due to the semantic gap. Therefore, we propose to map the multi-modal data into heterogeneous semantic spaces to capture their unique semantics. Specifically, we propose a novel software cross-modal retrieval framework named Deep Hypothesis Testing (DeepHT). In DeepHT, to capture the unique semantics of the code’s control flow structure, all control flow paths (CFPs) in the control flow graph are mapped to a CFP sample set in the sample space. Meanwhile, the text is mapped to a CFP correlation distribution in the distribution space to model its correlation with different CFPs. The matching score is calculated according to how well the sample set obeys the distribution using hypothesis testing. The experimental results on two text-to-code retrieval tasks (i.e., bug localization and code search) and two code-to-text retrieval tasks (i.e., vulnerability knowledge retrieval and historical patch retrieval) show that DeepHT outperforms the baseline methods. Hongwei Wei, Xiaohong Su, Weining Zheng, Wenxin Tao |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2021 | Vu1SPG: Vulnerability detection based on slice property graph representation learningabstractVulnerability detection is an important issue in software security. Although various data-driven vulnerability detection methods have been proposed, the task remains challenging since the diversity and complexity of real-world vulnerable code in syntax and semantics make it difficult to extract vulnerable features with regular deep learning models, especially in analyzing a large program. Moreover, the fact that real-world vulnerable codes contain a lot of redundant information unrelated to vulnerabilities will further aggravate the above problem. To mitigate such challenges, we define a novel code representation named Slice Property Graph (SPG), and then propose VulSPG, a new vulnerability detection approach using the improved R-GCN model with triple attention mechanism to identify potential vulnerabilities in SPG. Our approach has at least two advantages over other methods. First, our proposed SPG can reflect the rich semantics and explicit structural information that may be relevance to vulnerabilities, while eliminating as much irrelevant information as possible to reduce the complexity of graph. Second, VulSPG incorporates triple attention mechanism in R-GCNs to achieve more effective learning of vulnerability patterns from SPG. We have extensively evaluated VulSPG on two large-scale datasets with programs from SARD and real-world projects. Experimental results prove the effectiveness and efficiency of VulSPG. Weining Zheng, Xiaohong Su |
ISSRE | 1 |